CyberSec.Space Logo
Back to CVE Browser

CVE-2018-4878

Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score52.6350%
EPSS Percentile91.64th
PublishedFeb 6, 2018
Last ModifiedNov 18, 2025

Vulnerability Description

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

Affected Platforms (CPE)

πŸ“¦
Adobe

Flash Player

< 28.0.0.161
πŸ’»
Redhat

Enterprise Linux Desktop

= 6.0
πŸ’»
Redhat

Enterprise Linux Server

= 6.0
πŸ’»
Redhat

Enterprise Linux Workstation

= 6.0
πŸ“¦
Adobe

Flash Player

< 28.0.0.161
πŸ“¦
Adobe

Flash Player

< 28.0.0.161
πŸ“¦
Adobe

Flash Player

< 28.0.0.161

References & Advisories

Related Vulnerabilities